ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1083
File and Directory Discovery
MalwareSkidmap

Skidmap has checked for the existence of specific files including /usr/sbin/setenforce and /etc/selinux/config. It also has the ability to monitor the cryptocurrency miner file and process.

T1083
File and Directory Discovery
MalwareOkrum

Okrum has used DriveLetterView to enumerate drive information.

T1083
File and Directory Discovery
MalwareConti

Conti can discover files on a local system.

T1083
File and Directory Discovery
MalwareSameCoin

SameCoin can list all system files and can avoid wiping specific directories such as Program Files, Windows, and Users.

T1083
File and Directory Discovery
MalwareRaspberry Robin

Raspberry Robin will check to see if the initial executing script is located on the user's Desktop as an anti-analysis check.

T1083
File and Directory Discovery
MalwareMispadu

Mispadu searches for various filesystem paths to determine what banking applications are installed on the victim’s machine.

T1083
File and Directory Discovery
MalwareMegazord

Megazord can ignore specified directories for encryption.

T1083
File and Directory Discovery
MalwareDiavol

Diavol has a command to traverse the files and directories in a given path.

T1083
File and Directory Discovery
MalwareDoki

Doki has resolved the path of a process PID to use as a script argument.

T1083
File and Directory Discovery
MalwareSiloscape

Siloscape searches for the Kubernetes config file and other related files using a regular expression.

T1083
File and Directory Discovery
MalwareBlackCat

BlackCat can enumerate files for encryption.

T1083
File and Directory Discovery
MalwareFysbis

Fysbis has the ability to search for files.

T1083
File and Directory Discovery
MalwareMarkiRAT

MarkiRAT can look for files carrying specific extensions such as: .rtf, .doc, .docx, .xls, .xlsx, .ppt, .pptx, .pps, .ppsx, .txt, .gpg, .pkr, .kdbx, .key, and .jpb.

T1083
File and Directory Discovery
MalwareKazuar

Kazuar finds a specified directory, lists the files and metadata about those files.

T1083
File and Directory Discovery
MalwareNETEAGLE

NETEAGLE allows adversaries to enumerate and modify the infected host's file system. It supports searching for directories, creating directories, listing directory contents, reading and writing to files, retrieving file attributes, and retrieving volume information.

T1083
File and Directory Discovery
MalwarePOORAIM

POORAIM can conduct file browsing.

T1083
File and Directory Discovery
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP has the ability to enumerate directories for files that match a set list.

T1083
File and Directory Discovery
MalwareFatDuke

FatDuke can enumerate directories on target machines.

T1083
File and Directory Discovery
MalwareBlackEnergy

BlackEnergy gathers a list of installed apps from the uninstall program Registry. It also gathers registered mail, browser, and instant messaging clients from the Registry. BlackEnergy has searched for given file types.

T1083
File and Directory Discovery
MalwarezwShell

zwShell can browse the file system.

T1083
File and Directory Discovery
MalwareRising Sun

Rising Sun can enumerate information about files from the infected system, including file size, attributes, creation time, last access time, and write time. Rising Sun can enumerate the compilation timestamp of Windows executable files.

T1083
File and Directory Discovery
MalwareNotPetya

NotPetya searches for files ending with dozens of different file extensions prior to encryption.

T1083
File and Directory Discovery
MalwareShimRat

ShimRat can list directories.

T1083
File and Directory Discovery
MalwareObliqueRAT

ObliqueRAT has the ability to recursively enumerate files on an infected endpoint.

T1083
File and Directory Discovery
MalwareSHOTPUT

SHOTPUT has a command to obtain a directory listing.

T1083
File and Directory Discovery
MalwareAvaddon

Avaddon has searched for specific files prior to encryption.

T1083
File and Directory Discovery
MalwareXAgentOSX

XAgentOSX contains the readFiles function to return a detailed listing (sometimes recursive) of a specified directory. XAgentOSX contains the showBackupIosFolder function to check for IOS device backups by running ls -la ~/Library/Application\ Support/MobileSync/Backup/.

T1083
File and Directory Discovery
MalwareChina Chopper

China Chopper's server component can list directory contents.

T1083
File and Directory Discovery
MalwareLightSpy

LightSpy uses the `NSFileManager` to move, create and delete files. LightSpy can also use the assembly `bt` instruction to determine a file's executable permissions.

T1083
File and Directory Discovery
MalwareCheerscrypt

Cheerscrypt can search for log and VMware-related files with .log, .vmdk, .vmem, .vswp, and .vmsn extensions.

T1083
File and Directory Discovery
MalwareKeyBoy

KeyBoy has a command to launch a file browser or explorer on the system.

T1083
File and Directory Discovery
MalwareMiniDuke

MiniDuke can enumerate local drives.

T1083
File and Directory Discovery
MalwarePteranodon

Pteranodon identifies files matching certain file extension and copies them to subdirectories it created.

T1083
File and Directory Discovery
MalwareBeaverTail

BeaverTail has searched for .ldb and .log files stored in browser extension directories for collection and exfiltration.

T1083
File and Directory Discovery
MalwareROKRAT

ROKRAT has the ability to gather a list of files and directories on the infected system.

T1083
File and Directory Discovery
MalwareBabuk

Babuk has the ability to enumerate files on a targeted system.

T1083
File and Directory Discovery
MalwareExbyte

Exbyte enumerates all document files on an infected machine, then creates a summary of these items including filename and directory location prior to exfiltration to cloud hosting services.

T1083
File and Directory Discovery
MalwareDarkWatchman

DarkWatchman has the ability to enumerate file and folder names.

T1083
File and Directory Discovery
MalwareBlackMould

BlackMould has the ability to find files on the targeted system.

T1083
File and Directory Discovery
MalwarePACEMAKER

PACEMAKER can parse `/proc/"process_name"/cmdline` to look for the string `dswsd` within the command line.

T1083
File and Directory Discovery
MalwareBBSRAT

BBSRAT can list file and directory information.

T1083
File and Directory Discovery
MalwarePlugX

PlugX has a module to enumerate drives and find files recursively. PlugX has also checked the path from which it is running for specific parameters prior to execution.

T1083
File and Directory Discovery
MalwareBisonal

Bisonal can retrieve a file listing from the system.

T1083
File and Directory Discovery
MalwareMultiLayer Wiper

MultiLayer Wiper generates a list of all files and paths on the fixed drives of an infected system, enumerating all files on the system except specific folders defined in a hardcoded list.

T1083
File and Directory Discovery
MalwareDustySky

DustySky scans the victim for files that contain certain keywords and document types including PDF, DOC, DOCX, XLS, and XLSX, from a list that is obtained from the C2 as a text file. It can also identify logical drives for the infected machine.

T1083
File and Directory Discovery
MalwareRemsec

Remsec is capable of listing contents of folders on the victim. Remsec also searches for custom network encryption software on victims.

T1083
File and Directory Discovery
MalwareRover

Rover automatically searches for files on local drives based on a predefined list of file extensions.

T1083
File and Directory Discovery
MalwareEpic

Epic recursively searches for all .doc files on the system and collects a directory listing of the Desktop, %TEMP%, and %WINDOWS%\Temp directories.

T1083
File and Directory Discovery
MalwarePeppy

Peppy can identify specific files for exfiltration.

T1083
File and Directory Discovery
MalwareCuba

Cuba can enumerate files by using a variety of functions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.